cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1910
Views
0
Helpful
2
Replies

FMC "Blacklist IP Now" feature in Connection Events not working ?

craig.cordts
Level 1
Level 1

Does anyone know how the "Blacklist IP Now" feature in Connection Events should work. It seems to add the IP address to the "Global Blacklist" but I still see future connections from that IP being allowed. 

 

In the image below, 222.186.52.78 has been blacklisted. 

 

 

2 Replies 2

johnlloyd_13
Level 9
Level 9

hi,

You can Blacklist a Destination IP address (Responder IP) by doing a right-click on the specific IP > Blacklist IP Now.

see helpful link:

http://wannabecybersecurity.blogspot.com/2019/06/configuring-cisco-fmc-security.html


You can verify the added Blacklist IP by going again to Objects > Security Intelligence > Network Lists and Feed > Global-Blacklist > edit (pencil icon).

Thanks John-

 

What I am trying to do is Blacklist the Initiator IP. 

 

The FMC will allow me to select the initiator address and select Blacklist Now and it indeed gets successfully added to the Global Blacklist but future connections from that blacklisted address are still allowed based on the Connection Events log

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card